Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

·À·¶sql×¢Èë¹¥»÷£¨ÉÏ£©

ͬ²½Ò»ÏÂÎÒbaiduµÄblog£ºhttp://hi.baidu.com/ncheng/blog/item/bc65f82a1a6a7c335343c11c.html
Sql×¢ÈëÊÇÒ»ÖÖÈëÃż«µÍÆÆ»µ¼«´óµÄ¹¥»÷·½Ê½¡£Èç¹ûsqlÊÇÓÃ×Ö·û´®Æ´½Ó³öÀ´µÄ»°£¬ÄÇô¿Ï¶¨»á±»×¢Èë¹¥»÷£¬Ç°¶Îʱ¼ä»¹´«³öÁËij¹úÍâ´óÐÍÉç½»ÍøÕ¾±»SQL×¢Èë¹¥»÷¡£
Sql×¢Èë¹¥»÷µÄ·½Ê½£¬À´ÕâÀï¿´µÄͬ־ÃÇÓ¦¸ÃºÜÇå³þÁË£¬¾ÍÊÇÔÚÆ´½Ó×Ö·û´®µÄʱºò£¬Èç¹ûÊäÈëµÄÊÇ´øµ¥ÒýºÅµÄ£¬ÄÇôÊäÈëlaf' or 1='1' --ÕâÑù¾Í»áÌÓ±ÜÌõ¼þ¼ì²é£¬ºóÃæÒªÊÇÔÙ¸úһЩshutdown£¬deleteÖ®ÀàµÄÌõ¼þ£¬ÄÇôËðʧ»ù±¾ËãÊÇ»ÙÃðÐÔµÄÁË¡£Ç°¼¸Ì쵥λ¿ª·¢µÄ¹ý³ÌÖÐÎÒ·¢ÏÖ¼¸ºõ´ó¼Ò¶¼²»ÖØÊÓ°²È«£¬Ò»¸öд´úÂëµÄÈ˲»×¢ÒⰲȫֻעÒâʵÏÖÄÇôд³öÀ´µÄ´úÂëÔÚ¹¥»÷ÕßÑÛǰ»ù±¾¾ÍÊÇÒ»¸öûÓд©Ò·þµÄÃÀÅ®¡£
ÏÂÃæÊÇÎÒÒ»¸ö¿ª·¢ÈËÔ±µÄһЩ¾­Ñ飬Ö÷ÒªÓÃÀ´·ÀÖ¹sql×¢Èë¡£
1¡¢Ê×ÏȶÔÔËÐÐsqlµÄÓû§¸³Óè×îСȨÏÞ£¬Õâ¸öÀíÂÛÒ²Êǰ²È«ÁìÓòµÄ×îÐ¡ÌØÈ¨ÀíÂÛ£¬ÔËÐÐÒ»¸ö³ÌÐòÒ»¶¨ÒªÓÃ×îÐ¡ÌØÈ¨ÔËÐУ¬ËùÒÔ²»Òª¸øÓû§·þÎñDBAµÄȨÏÞ£¬ÏÞÖÆÒªÈ¨ÏÞÖ®ºó¿ÉÒÔ·ÀֹһЩ»ÙÃðÐԵĹ¥»÷£¬¼´Ê¹¹¥ÈëÁËÒ²²»»áshutdownÐ޸ıíÖ®ÀàµÄ¡£
2¡¢Ò»¶¨²»ÒªÊ¹ÓÃ×Ö·û´®Æ´½ÓµÄ·½Ê½¹¹Ôìsql£¬±ØÐëʹÓòÎÊý»¯sql£¬´æ´¢¹ý³Ì¿ÉÒÔ¿´×÷ÊDzÎÊýsql£¬¼òµ¥µÄ¾ÍÖ±½Ó¹¹Ôì²ÎÊý»¯sql£¬¸´ÔӵľÍд´æ´¢¹ý³Ì£¬²»¹ý´æ´¢¹ý³ÌÖÐÒ»¶¨²»ÒªÓÃ×Ö·û´®£¬ÎÒ¿´ÓÐÈËÔÚ´æ´¢¹ý³ÌÓÃ×Ö·û´®£¬ÕâÑù»¹ÊDz»ÄܱÜÃâ±»¹¥»÷£¬²¢ÇÒÔÚµ÷ÊÔµÄʱºò·Ç³£Âé·³¡£
3¡¢ÑϰÑÊäÈë¹Ø£¬ÏµÍ³¿Ï¶¨ÊÇÓÃÀ´½»»¥µÄ£¬ËùÓÐÓû§ÊäÈëµÄÕâÒ»¹ØÒ»¶¨Òª°ÑºÃ£¬¿ÉÒÔÀûÓø÷ÖÖ·½Ê½À´¼ìÑéÓû§µÄÊäÈ룬ÈÃÊäÈë¶¼ÊǺϷ¨µÄ£»¿ÉÒÔÉèÃô¸Ð×Ö·û²»ÈÃÓû§ÊäÈ룬Õâ¸öËäÈ»²»ÊǺÜÓѺ㬲»¹ý¶ÔÓ밲ȫÓб£Ö¤¡£ÔÚÑéÖ¤µÄÊÇ¿ÉÒÔÓÃÕýÔò±í´ïʽ»òÕß³ÌÐòÑéÖ¤£¬²»¹ÜÓÃʲô·½Ê½Ö»Òª°ÑÃô¸Ð×Ö·ûºÍ¿ÉÒÉ×Ö·û¾ÜÖ®ÃÅÍâÄÇô¾ÍÎÞ·¨¹¥»÷ÁË£¬²»¹ýÏÞÖÆÊäÈ뻹ÊÇÓÐȱÏÝ£¬ÔÚ°²È«ÀíÂÛ·½Ã棬ֻÄÜÈ·¶¨ºÏ·¨£¬²»ÄÜÈ·¶¨²»ºÏ·¨£¬±ÈÈçÄãÔÚ½çÃæÏÞÖÆÁ˺Ϸ¨µÄ£¬ÄÇôʣÓàµÄ¶¼ÊDz»ºÏ·¨µÄ£¬ÕâʱºòÊäÈëµÄ¿Ï¶¨È«²¿ÊǺϷ¨µÄ£¬Èç¹ûÄãÏÞÖÆµÄÊÇ·Ç·¨µÄ£¬¿ÉÊÇÄãÄÜÈ·±£ÄãÏÞÖÆµÄÈ«ÊÇ·Ç·¨µÄ£¿Èç¹ûijһÌì·¢ÏÖÒ»¸ö·Ç·¨µÄ²»ÔÙÄãÏÞÖÆÖ®ÄÚÄÇôÄã¾Í»á±»¹¥»÷¡£
4¡¢×öºÃ×Ô¼ºµÄ¼ìÑéºÍ²âÊÔ¹¤×÷£¬×Ô¼º¿ÉÒÔ½øÐÐsql×¢Èë¹¥»÷£¬ÀûÓù¤¾ß¼ìÑé¡£
5¡¢Ò»¶¨ÒªÑø³É¾ßÓа²È«ÒâʶµÄ³ÌÐòÔ±£¬Ê±¿ÌÏë×Ű²È«¡£
 
Õ⼸ÌõÖ®ÖÐ×îÖØÒªµÄÊÇ1ºÍ2£¬È¨ÏÞÏÞÖÆÒ»¶¨Òª×¢Ò⣬²»È»»áËÀµÄºÜ²ÒµÄ£¬µÚ¶þ¾ÍÊdzÌÐòÔ±µÄϰ¹ßÁË£¬Ò»¶¨ÒªÓòÎÊý»¯sqlºÍÊý¾Ý¿â½»»¥¡£
 
ʱ¼äÌ«ÍíÁË£¬Ã÷Ì컹ҪÉϰàÄØ£¬¾Íµ½ÕâÀï°É£¬ÏÂһƪÎÒ¾Íͨ¹ýʵÀýÀ´ËµËµ³ÌÐòÔ±×î¹ØÐĵ


Ïà¹ØÎĵµ£º

½â¾öSQL¡¡SERVER2005²»ÄÜÔ¶³ÌÁ¬½ÓÎÊÌâ

¸Õ×°ÍêÊý¾Ý¿â¾Í±»ÈË·è¿ñɨÃèsa£¬ÎÞ±ÈÓôÃÆ¡£
¸ÄsaÃû³Æ£¬1433¶Ë¿ÚºÅ£¬ÒòΪ¿ª·¢ÐèÒª»¹±ØÐë´ò¿ªÔ¶³ÌÁ¬½Ó£¬½á¹ûÔÚ¿Í»§¶ËÎÞÂÛÈçºÎ¶¼²»ÄÜÁ¬½ÓÉÏ·þÎñÆ÷¡£
¿ñº¹Çë°Ù¶È´óÉñ³öÂí£¬°Ñ¸÷ÖÖÅäÖÃÁ·Á˸öÊ죬½á¹û»¹ÊÇû½â¾ö¡£
¸ãЦµÄÊÇ×îºóÎÞÒâÖÐÔÚMicrosoftÂÛ̳ÉÏ¿´µ½Õâôһ¾ä£¬ÐÞ¸ÄÍê¶Ë¿ÚºÅ£¬ÔÚ¿Í»§¶ËµÇ¼µÄʱºòÒªÔÚIPºóÃæ£«¶ººÅ£«¶Ë¿Úº ......

ÓÃÃüÁîÐÐÖ´ÐÐSQL½Å±¾Óï·¨½âÎö

osql   ʵÓù¤¾ß  
  osql   ʵÓù¤¾ßʹÄúµÃÒÔÊäÈë   Transact-SQL   Óï¾ä¡¢ÏµÍ³¹ý³ÌºÍ½Å±¾Îļþ¡£¸ÃʵÓù¤¾ßͨ¹ý   ODBC   Óë·þÎñÆ÷ͨѶ¡£  
   
  Óï·¨  
  osql  
          [-?]   |  
&nb ......

²éѯ´æ´¢¹ý³ÌµÄ²ÎÊýÐÅÏ¢µÄSQLÓï¾ä

declare @SchemaName nvarchar(50)
set @SchemaName='dbo'
declare @CommandName nvarchar(50)
set @CommandName='spName'
SELECT
                DB_NAME() AS [PROCEDURE_CATALOG],
         ......

SQL »ù±¾²Ù×÷ ɾ³ý ÐÞ¸Ä Ë¢Ð Ð޸İæ

C# Êý¾Ý¿âÖ®ÂÃ……
¼ÌÐø½ø¹¥²ã³ö²»ÇîµÄproblems
ÔÚÉÏһƪÄÚÈݵĻù´¡ÉÏ£¬ÎÒÓÖ×÷ÒԸĽø£¬ÏÖÔÚµÄÇé¿öÊÇÕâÑùµÄ£º
 //In Browseuser form
using System;
using System.Collections.Generic;
using System.ComponentModel;
using System.Data;
using System.Drawing;
using System.Linq;
using System ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ